IBM Support

Security Bulletin: IBM Tivoli Monitoring (CVE-2015-1829, CVE-2015-3183, CVE-2015-1283, CVE-2015-4947, CVE-2015-2808)

Security Bulletin


Summary

IBM Tivoli Monitoring utilizes the IBM HTTP Server (IHS) as the default HTTP server for the portal server. IBM HTTP Server is affected by the following CVEs as listed below: CVE-2015-1829, CVE-2015-3183, CVE-2015-1283, CVE-2015-4947, CVE-2015-2808.

Vulnerability Details

CVEID: CVE-2015-1829
DESCRIPTION:
Apache Portable Runtime is vulnerable to a denial of service, caused by an error when using APR named pipe support on Windows. An attacker could exploit this vulnerability to cause a pipe squatting attack on a local process.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/103204 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVEID: CVE-2015-3183
DESCRIPTION:
Apache HTTP Server is vulnerable to HTTP request smuggling, caused by a chunk header parsing flaw in the apr_brigade_flatten() function. By sending a specially-crafted request in a malformed chunked header to the Apache HTTP server, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
CVSS Base Score: 6.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104844 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

CVEID: CVE-2015-1283
DESCRIPTION:
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
CVSS Base Score: 6.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104964 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)

CVEID: CVE-2015-4947
DESCRIPTION:
IBM HTTP Server Administration Server could be vulnerable to a stack buffer overflow, caused by improper handling of user input. An authenticated remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104912 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2015-2808
DESCRIPTION:
The RC4 algorithm, as used in the TLS protocol and SSL protocol, could allow a remote attacker to obtain sensitive information. An attacker could exploit this vulnerability to remotely expose account credentials without requiring an active man-in-the-middle session. Successful exploitation could allow an attacker to retrieve credit card data or other sensitive information. This vulnerability is commonly referred to as "Bar Mitzvah Attack".
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/101851 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

Affected Products and Versions

The following IBM Tivoli Monitoring portal server releases (cq component):
IBM Tivoli Monitoring version 6.23 through 6.23 FP5
IBM Tivoli Monitoring version 6.30 through 6.30 FP6

Remediation/Fixes

IBM Tivoli Monitoring 6.2.3:
The following link includes instructions for installing the updates to the IBM HTTP Server (IHS) 7,0 for IBM Tivoli Monitoring portal server version 6.2.3.
https://www.ibm.com/developerworks/community/blogs/0587adbc-8477-431f-8c68-9226adea11ed/entry/apply_maintenance_to_the_ibm_http_server_installed_with_ibm_tivoli_monitoring?lang=en

The following patches should be downloaded and installed using the steps provided in the link above: The updates include IHS Fix Pack 7.0.0.37 and the interim fixes as listed below.

IBM Tivoli Monitoring 6.3.0
The following link contains a package to upgrade IBM HTTP Server to version 8.0.0.11 plus interim fixes PI45596, PI42928, PI44793: http://www.ibm.com/support/docview.wss?uid=swg24041169

Get Notified about Future Security Bulletins

References

Off

Change History

30 Aug 2016 Corrected broken link.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Internal Use Only

Advisory 3235
Advisory 3455
Advisory 3672
Advisory 3520

[{"Product":{"code":"SSZ8F3","label":"IBM Tivoli Monitoring V6"},"Business Unit":{"code":"BU004","label":"Hybrid Cloud"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"6.2.3;6.3.0","Edition":""}]

Product Synonym

ITM

Document Information

Modified date:
17 June 2018

UID

swg21970056